Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

David Attlee46 minutes agoMistake or money laundering? User pays $1.6 million for CrypToadz NFTThe purchase was funded from a digital wallet, which has been a part of the chain of transactions, anonymized by the Ethereum
Turner Wright6 hours agoVitalik Buterin calls X’s Community Notes an example of ‘crypto values’The Ethereum co-founder said the algorithm behind X’s tool to rate content as helpful and provide context was “surp
Biggest Movers: XMR Moves to 5-Week High, Despite Crypto Selloff
Biggest Movers: XMR Moves to 5-Week High, Despite Crypto Selloff Monero moved to its highest level in five weeks on Thursday, despite crypto markets mainly trading in red. The toke
Bitmex Agrees to Pay $100 Million to Resolve Charges With FinCEN and CFTC
Bitmex Agrees to Pay $100 Million to Resolve Charges With FinCEN and CFTC Global cryptocurrency derivatives exchange Bitmex has settled charges with the U.S. Com
US Senator Proposes Congress Adopt Cryptocurrency for Payments
US Senator Proposes Congress Adopt Cryptocurrency for Payments U.S. Senator Ted Cruz has introduced a resolution that would position Congress to lead in the area of cryptocurrency
ApeCoin holders mull proposal for Bored Ape-themed hotel in Bangkok
Tom Mitchelhill6 hours agoApeCoin holders mull proposal for Bored Ape-themed hotel in BangkokA member of the ApeCoin DAO is asking for $356,000 to renovate a portion of a hotel in downtown Bangkok with Bored Ape Yacht Cl
Technical Analysis: Flow Climbs Close to 30% to Enter Top 50
Technical Analysis: Flow Climbs Close to 30% to Enter Top 50 Flow is trading almost 30% higher on Saturday, as the majority of the crypto top 100 are in the green. Today’s m
BUSD Stablecoin Drops from Top 10 Crypto Assets Amid Significant Decrease in Dominance
BUSD Stablecoin Drops from Top 10 Crypto Assets Amid Significant Decrease in Dominance After Paxos announced that it would no longer mint the stablecoin BUSD, 4.98 billion BUSD sta
Centralized Exchange Operators Believe Low Liquidity on DEX Platforms Stops User Migration
Centralized Exchange Operators Believe Low Liquidity on DEX Platforms Stops User Migration Centralized cryptocurrency exchanges (CEX) operators say they are unfa
Cointelegraph Innovation Circle8 hours agoNavigating the crypto frontier: Pioneers’ insights for new Web3 professionalsThe crypto and blockchain industry still offers unlimited possibilities if you come in with your ey
Is The XRP Bottom In? Pundit Claims ‘Sellers Are Exhausted’
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Derek Andersen6 hours agoOctober sees a comparative lull in crypto crime with losses of $32.2M: CertiKThere is no clear downward trend in crypto crime, but a quiet month is undoubtedly more than welcome in the Web3 commu